Privacy Policy
Terma helps you keep track of what you pay, renew, or cancel. This page explains exactly what data the app touches, and where it goes — in plain language, matching what the app actually does, not a generic template.
1. Local-first storage
By default, every subscription, contract, and warranty you add stays only in the app's local storage (IndexedDB and localStorage) on the device you're using. We — the people who run terma — never see this data, cannot access it, and it never leaves your device unless one of the sections below applies.
2. Signing in
Signing in is optional and only needed to unlock paid features or sync across devices. It works without a password:
- You enter your email address. We store it to identify your account.
- We send a one-time sign-in link (via our email provider, Resend). The link expires after 15 minutes and can only be used once.
- Once signed in, your device holds a session token (not your email or a password) that proves who you are on later requests.
- When you create an account specifically to upgrade to Plus, Pro, or the one-time "remove ads" purchase, we also record the timestamp you accepted the Terms of Service and Privacy Policy, and whether you opted in to occasional product emails. Signing in without a purchase in mind (e.g. just to sync a free account) doesn't ask for or store this.
3. Cross-device sync (Pro only)
If you're on the Pro plan and signed in, your subscription and contract records (amounts, renewal dates, categories — not the scanned document files themselves, those stay local to each device) are stored on our server so they show up on your other devices too. This is the only case where your subscription data leaves your device. Free and Plus accounts, and anyone not signed in, are unaffected — nothing syncs for them.
4. AI document scanning and price lookup
When you scan a document or ask terma to look up a price, the relevant content (the document image/text, or a brand name and country) is sent to Google's Gemini API to be read. This happens through our own server, which does not log, store, or retain that content afterward — it's a pass-through. Google processes it under its own API terms.
5. Brand icons
To show a recognizable icon next to a service in your list (e.g. Netflix, Spotify), the app loads it directly from Google's public favicon service, based on that service's domain name. Your device contacts Google directly for this image; no account or subscription data is sent along with it, and we don't store any brand logos on our own servers.
6. Payments
If you upgrade to a paid plan, payment is handled entirely by Google Play Billing (Android app). We never see or store your card details — that data goes directly to Google, never to our own servers.
7. What we don't do
| Advertising (free tier only) | Free-tier users may see a full-screen ad from Google Ad Manager while a document is being scanned. Plus and Pro never show ads. The ad network doesn't receive your documents, contracts, or account data — only the standard, anonymous context Google's ad system needs to pick an ad (like your general region). |
|---|---|
| No profiling trackers | We don't run Google Analytics, Meta Pixel, or similar tools that follow you across sites or build a profile of you. |
| No data sale | We never sell, rent, or trade your data to anyone. |
| No cookies for tracking | Terma doesn't use tracking cookies. Sessions are handled via a token you hold, not a cookie we plant. |
8. Anonymous usage counts
To check that the app actually works as intended (e.g. whether people can find and use the upgrade screen, or successfully add a subscription), a few key moments — opening the plan screen, tapping an upgrade button, adding an item, finishing a scan, creating an account — increment an anonymous daily counter on our own server. Each count is just a number attached to a date and an event name; nothing ties it to your email, account, or device, and it's never shared with anyone outside terma.
9. Your rights
You can export or permanently delete everything stored locally at any time from within the app (Settings). For data we hold on our server (your email, and — if you're Pro and signed in — your synced items), you can request deletion by emailing us at the address below; we don't yet have a fully self-service "delete my account" button in the app, so for now this goes through us directly. If you're in the EU/EEA, this reflects your rights under the GDPR (access, correction, deletion, and portability of your data).
10. Changes to this policy
If what the app does with your data changes in a meaningful way, we'll update this page and change the date at the top.
11. Contact
Questions about this policy or a data request: [email protected]